Sirran

Privacy Policy

Effective date: 6 August 2026

App: Sirran (iPhone, Apple Watch, Android phone, Wear OS)

Publisher: Baris Demircan

Contact: barisdemircan@outlook.com.tr

Sirran has no user accounts, advertising SDK, advertising identifier, or first-party analytics service. Prayer calculations, Qibla, bundled Quran reading, and tasbih data are processed on your device. Optional Nearby Mosques, official prayer-timetable, store, and Quran Foundation online-content features make only the limited requests described below.

What the publisher does not collect directly

No advertising or analytics SDK

The Android, iPhone, Apple Watch, and Wear OS builds contain no advertising SDK, analytics SDK, or advertising-ID permission. Sirran Plus supports independent development; it does not remove advertising because advertising is absent for everyone.

Quran Foundation ecosystem and Content APIs

Sirran is an independent product and is not an official application of, affiliated with, or endorsed by Quran Foundation. On Android, Sirran's optional online Quran reader uses the Quran Foundation Content APIs to retrieve the Dar Al-Salam Center Turkish translation (translations:210), Mishari Rashid al-‘Afasy ayah recitation (recitations:7), and—only in an explicitly enabled build and resolved Arabic reader—the user-selected Tafsir al-Muyassar (tafsirs:16, ar-tafsir-muyassar) from the Quran.com ecosystem. QuranReflect is part of Quran Foundation's wider ecosystem; Sirran does not access QuranReflect accounts, private reflections, bookmarks, notes, reading history, or other Quran Foundation user data.

Quran Foundation provided written authorization for the requested commercial in-app use and long-term offline retention on 19 July 2026. On 30 July 2026, Quran Foundation expressly confirmed that Sirran may initialize translations:210 and recitations:7 from the direct snapshot endpoints, check Content Sync daily with the same resource filter, and retain those resources on users' devices for the user-initiated in-app offline experience. Production credentials remain provisioned only on Sirran's server. Reader, synchronization, caching, and offline-download access is available only in explicitly enabled Android builds and only after the user's affirmative opt-in action. The backend uses the OAuth2 client_credentials flow for application access and does not receive an end-user OAuth token. Public-content requests are keyed by content resource rather than a user or device. On 6 August 2026 Quran Foundation separately confirmed the identity, attribution and commercial/freemium in-app display permission for the selected-ayah Tafsir al-Muyassar surface without requiring a separate third-party licence.

Sirran's Production integration runs on Cloudflare Workers so Quran Foundation credentials remain server-side and are never embedded in the app. Ordinary reader and audio-delivery responses are marked private, no-store. For the approved retained-content feature, Sirran's backend stores integrity-validated public Quran-content bundles and catalogue metadata for translations:210 and recitations:7; this retained material is not linked to a Sirran account, device identifier, reading history, bookmarks, notes, or worship activity. Audio bytes are not retained in the backend content cache.

The Arabic tafsir path is distinct from that retained translation/recitation flow. It runs only after affirmative QF consent, only when the resolved reader language is Arabic, and only after the user selects a specific ayah. The requested surah and ayah identifier and ordinary HTTPS connection data pass through Sirran's server-side proxy; the tafsir response is ephemeral and marked private, no-store. Sirran does not prefetch, cache, download or retain the tafsir text, and does not create or link it to an account, device identifier, reading history, bookmark, note, subscription or advertising profile. The surface remains available regardless of subscription status and contains no advertising, subscription benefit or upsell. It is unavailable offline.

The source is Tafsir al-Muyassar (التفسير الميسر), prepared by a committee of scholars under the supervision of the King Fahd Glorious Quran Printing Complex. Quran Foundation requested one localized visible credit and clarified that it is not a formal licence condition. The Arabic-only surface uses التفسير الميسر — مجمع الملك فهد لطباعة المصحف الشريف; corresponding English documentation may use “Tafsir al-Muyassar — King Fahd Glorious Quran Printing Complex”. Sirran is independent and does not use Quran Foundation or Quran.com logos for this surface.

Sirran checks Quran Foundation Content Sync daily and applies reported updates, invalidations, and removals. After consent, Android may retain the approved Turkish translation and recitation catalogue in app-private, non-backed-up device storage. Audio is retained only after the user starts an in-app download. Approved content may remain usable while a device is offline for longer than seven days; when connectivity returns, Sirran synchronizes as soon as reasonably possible and applies relevant changes. Audio files cannot be exported or shared as standalone downloads or used outside Sirran. All Quran Foundation reading and recitation content remains available regardless of paid subscription status.

Sirran does not use end-user QF OAuth/OIDC, sign users into Quran Foundation accounts, or request user-data scopes. Any future QF account, bookmark, note, reflection, reading-history synchronization, or other user-data feature remains disabled until separately reviewed and disclosed.

Sensitive religious information

Prayer preferences, reading or recitation history, notes, reflections, worship logs, tasbih counts, and similar data may reveal religious beliefs and can be sensitive personal data. Sirran keeps saved versions of these items on the device and does not create or retain a user-linked reading-history or worship profile on a publisher server. An opted-in QF public-content request transiently processes the requested resource identifier and ordinary connection data as described above. If a future feature needs publisher-server collection or synchronization of saved religious information, it will remain off until the user gives a separate, explicit, affirmative opt-in that is not bundled into general acceptance of the Terms of Use. Data will then be limited to the disclosed feature and purpose.

The Android implementation includes a separate consent screen that explains the requested content identifiers, ordinary connection data, app-private retention, user-started audio downloads, extended offline use, reconnection synchronization, and the prohibition on standalone export. The feature makes no QF request unless an explicitly enabled release switch, a safe proxy endpoint, and the user's affirmative opt-in are all active. The user can withdraw consent in Settings. Withdrawal stops future QF requests, cancels an active QF download, clears the consent state, and deletes downloaded or cached QF content from the device. The bundled Quran and unrelated local reading data remain available.

Nearby Mosques (optional, Android only)

When you open Nearby Mosques, Sirran rounds the device coordinate to four decimal places (about 11 metres of latitude resolution) and sends it to public OpenStreetMap Overpass instances to find mosques progressively within 2 km, 5 km, and at most 10 km. Google Play classifies this four-decimal coordinate as Precise location, even though it is rounded. The app may try more than one public instance when a server is unavailable. This happens only when you use that feature. The publisher does not store the coordinate or the results on a server. On the phone, an in-process cache keeps the four-decimal coordinate key, search radius, result list, and cache time. A result is treated as fresh for 10 minutes and may be shown as explicitly stale after a network failure for up to 24 hours. This cache is not written to disk and disappears when the app process ends. There is no Sirran account. Tapping a result opens your maps app for directions.

Official prayer timetable (optional)

The default calculation works locally. If you explicitly select an official timetable and confirm a supported place, Android sends only that public place identifier, the requested date range, and its time zone to the configured Sirran timetable adapter over HTTPS. It does not send your GNSS coordinate, prayer history, Quran activity, microphone audio, or an advertising identifier. Authority credentials are never embedded in the app. Hosting and network providers necessarily process connection data such as an IP address to deliver an internet response.

Store purchases

On Android, Google Play Billing is used to offer and restore Sirran Plus. Google handles account and payment information under its own terms. Sirran stores the resulting entitlement locally and does not receive or store your payment-card details. The current iPhone launch configuration has in-app purchases disabled and is submitted as a free app with no in-app purchases; StoreKit support in the code is inactive in that build.

Third-party services and recipients

Sirran does not disclose worship activity for advertising or unrelated profiling. The following services may receive only the information needed for the user-requested feature:

Where a provider processes personal data on Sirran's behalf, the corresponding feature will be enabled only with appropriate data-protection terms and instructions that prohibit unrelated use and misuse of Quranic content. Public endpoints that act independently are recipients/controllers under their own policies rather than Sirran subprocessors. Sirran does not send Quran Foundation user data to OpenStreetMap, Google, Apple, or GitHub for unrelated use. Any future QF account or user-data feature stays disabled until its additional legal, security, privacy, and Islamic-content protection controls have been verified.

On-device data and permissions

The app uses the following only on your device, to provide its features:

Bundled Quran content

The Quran text in the app is "Tanzil Quran Text (Simple)" from the Tanzil Project (tanzil.net), used under the Creative Commons Attribution 3.0 license with in-app attribution. The bundled translation is "The Meaning of the Glorious Koran" by Marmaduke Pickthall (1930, English), which is in the public domain and shown with in-app attribution. No Turkish meal is packaged with the app installation, so before the user enables and downloads the optional QF content, offline reading uses the bundled Arabic Quran and bundled Pickthall translation. Opening and reading this bundled corpus does not make a network request. On Android, after affirmative consent, the user may retain the Dar Al-Salam Center translations:210 meal and user-selected recitations:7 audio for offline use through the separate retained data flow described above. Tafsir al-Muyassar ID 16 is not bundled or retained; in an enabled Arabic reader it is fetched only for a user-selected ayah through the ephemeral path described above.

Sirran preserves Quran text unchanged, presents excerpts in context, and shows source attribution. QF content is not used for advertising profiles, biometric identification, or machine-learning training.

Children's privacy

Sirran is not directed to children under 13. It does not ask for a date of birth, has no sign-up flow, and therefore cannot accept an underage account registration. It does not knowingly collect children's personal data. Parents and guardians should supervise a child's use of religious content and optional network features.

Data security and retention

Sirran operates no first-party account or worship-history server. App settings (such as your selected city, madhab, and tasbih counts) are stored locally and are removed when you delete them in the app, clear app storage, or uninstall the app. The Nearby Mosques process cache has the 10-minute fresh/24-hour stale limits described above. Wear OS Data Items have Google Play services' persistent lifecycle described above and are overwritten when Sirran publishes newer state; they are not a publisher-server copy.

All Sirran-controlled network endpoints, including the deployed QF reader proxy, require HTTPS. QF credentials remain only in the server secret store and access is least-privilege. Production secrets must rotate at least every 90 days and immediately after suspected exposure. These controls are aligned with the QF Developer Privacy Packet's Security Rule 6.9. Sirran will begin responding to an actual or suspected API security incident in less than 24 hours and will report it to Quran Foundation no later than 24 hours after detection when QF systems or data may be affected.

The reader proxy does not add a Sirran user ID, device ID, advertising ID, or reading-history identifier to QF requests. It processes the requested resource identifier plus ordinary connection data such as IP address and request time; any IP address/resource-identifier combination visible to the infrastructure is handled by Cloudflare and Quran Foundation under their published policies. Ordinary reader, tafsir and audio-delivery responses are private, no-store. The selected-ayah tafsir body is not written to Sirran's backend retained store or Android storage. Sirran's retained backend store contains only integrity-validated public Quran-content bundles and catalogue metadata; it does not contain a QF user-data backup or reading-history profile. Approved content stored on Android remains in app-private, non-backed-up storage until the user deletes the relevant audio, withdraws consent, clears app storage, or uninstalls Sirran. Sirran checks Content Sync daily, and a device that reconnects applies relevant updates, invalidations, or removals as soon as reasonably possible. If a future server feature stores user data, a verified deletion request will hard-delete it from live systems within 30 days and from backups within 90 days, unless a shorter legal period or lawful retention duty applies. Other requests are handled under each recipient's published retention and security practices.

Your rights and controls

You can deny or revoke optional operating-system permissions, disable optional features, delete feature data using the available in-app controls, clear app storage, or uninstall Sirran. Depending on applicable law, you may ask to access, correct, delete, restrict, object to, or obtain a copy of personal data controlled by the publisher. Send a verified request to the contact below; the publisher will respond within 30 days.

Sirran does not use end-user QF OAuth/OIDC or associate local data with a QF account. The backend application token is not an end-user token, so there is currently no user-granted Sirran QF token to revoke, and deleting a Quran Foundation account does not leave linked Sirran server data. End-user revocation controls, an OAuth revocation link, and an in-app server-data deletion mechanism will be added before any QF account/user-data integration ships.

International data transfers

Optional network providers may process ordinary connection data outside your country. Where Sirran selects a processor and cross-border transfer safeguards are legally required, Sirran will rely on the European Commission's Standard Contractual Clauses or an equivalent lawful mechanism and will comply with applicable local transfer laws. Independently operated public endpoints and app stores process data under their own policies and legal roles.

Changes to this policy

If the app's data practices change, this policy and relevant app-store disclosures will be updated before the change ships. The effective date above will change. Material changes will be announced through an in-app notice and, where the publisher has a user's contact address for a requested service, by email when appropriate.

Contact

Questions or privacy-rights requests:

See also the Sirran Terms of Use and Support page.